Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-12608

Опубликовано: 07 мая 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:managed_service_provider_patch_management_engine:*:*:*:*:*:*:*:*
Версия до 1.1.15 (исключая)

EPSS

Процентиль: 89%
0.04394
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-276

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

EPSS

Процентиль: 89%
0.04394
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-276